Microsoft Defender XDR
General

What's new in Microsoft Defender XDR

In brief

The page now lists Agent 365 agent threat detection as Preview, tooling-server real-time protection as GA, and the Security Copilot Threat Hunting Assistant as GA under its updated name.

What Defender admins need to know

Administrators should use the updated availability and feature names when reviewing Defender capabilities. No administrator action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

What's new in Microsoft Defender XDR

  • (GA) The Domain investigation page allows you to investigate an Active Directory domain. It shows Active Directory domain security, including domain properties, deployment health, identity summary, service account breakdown, sensitive entities, active recommendations, group policies, and trust relationships. For more information, see Investigate a domain.

  • (GA)Preview) SecurityThreat detection for Microsoft Agent 365 with Defenderagents: With aMicrosoft Defender analyzes runtime signals from agent interactions, tool usage, and execution patterns to surface alerts in Microsoft Defender XDR. Detection uses observability data from Microsoft Copilot Studio, Microsoft Foundry, Microsoft 365 Copilot Agent Builder, and agents integrated through the Microsoft Agent 365 license, Microsoft Defender provides discovery, security posture, threat detectionSDK. Analysts can investigate alerts through incidents and investigation, and real-time protection for the AI agents in your tenant. Onboarding includes enabling data collection, connecting the Microsoft 365 app connector, and connecting Copilot Studio for real-time protection of Copilot Studio agents.advanced hunting. For more information, see Protect AI agents using Microsoft DefenderDetect and investigate threats to AI agents using Microsoft Defender.

  • (GA) Real-time protection for Microsoft Agent 365 tooling servers: Microsoft Defender evaluates tool invocations and Enable security for AI agents using Microsoft Defenderresponses against security policies and can allow or block interactions with Work IQ MCP and customer MCP tools onboarded to Agent 365. For more information, see Protect AI agents in real time using Microsoft Defender.

June 2026

  • (Preview) Microsoft Security Copilot in Microsoft Defender now includes the Dynamic Threat Detection Agent, an always-on, adaptive backend service that uncovers hidden threats across Defender and Microsoft Sentinel environments. Learn more
  • (GA) The Microsoft Security Copilot Threat Intelligence Briefing Agent in Microsoft Defender is now generally available. It generates threat intelligence briefings based on the latest threat actor activity and both internal and external vulnerability information in a matter of minutes, helping security teams save time by creating customized, relevant reports.
  • (Preview)GA) Microsoft Security Copilot in Microsoft Defender now lets you hunt for threats by using natural language with the Threat Hunting AgentThreat Hunting Assistant. This agent delivers a complete, conversational threat hunting experience by not only generating queries but also interpreting results, surfacing insights, and guiding you through full hunting sessions.
  • (Preview) The following advanced hunting schema tables are now available for preview:
    • The CampaignInfo table contains information about email campaigns identified by Microsoft Defender for Office 365.
    • The FileMaliciousContentInfo table contains information about files that Microsoft Defender for Office 365 processed in SharePoint Online, OneDrive, and Microsoft Teams.
    • The MessagePostDeliveryEvents table contains information about security events that occurred after the delivery of a Microsoft Teams message in your organization
    • The MessageUrlInfo table contains information about URLs sent through Microsoft Teams messages in your organization